Please report security issues privately to the maintainers before public disclosure.
Include:
- affected version/commit
- reproduction steps
- expected vs observed behavior
- impact assessment
- Latest minor release: full support.
- Previous minor release: best-effort critical fixes.
Recommended rotation cadence:
- OAuth client secrets: every 90 days or after incident.
- token encryption keys: every 90 days with a documented rollover plan.
- webhook signing secrets: every 90 days.
- HTTPS enforced at edge/app layer.
- Secure cookies enabled.
- Security headers configured (HSTS, CSP, X-Frame-Options or equivalent).
- Dependency + secret scanning in CI.